Malware

What is “Mal/Frethog-B”?

Malware Removal

The Mal/Frethog-B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Frethog-B virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Creates a copy of itself

Related domains:

zipansion.com
hurirk.net

How to determine Mal/Frethog-B?


File Info:

crc32: 60BBEC18
md5: 4303b653b0dca78ac8b41dc41c61fd43
name: 4303B653B0DCA78AC8B41DC41C61FD43.mlw
sha1: 95f1dd5af8b0c6c1c4f21e6ec14951786c1ac338
sha256: 4c5c80b2ea7ba7574a3b3a785ebbe212ca11b6a627a842eb5ba3f49d01517964
sha512: 207f806c8e4be3f414ea68ec9dfef6c3165a5686374c1c73f574c888f1733eb26bae82ff32716746f070f8995a648de057928daa2ed81759ee3bcedf3d7704bd
ssdeep: 24576:WshDwfMiLVyB3laDHzd1pLmaX2Y5gF5re7B5Ix9I6m1cbQCxCHU9/9Us:WsBwfMisZlKzDpLmU5goB+/sCxxR9j
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Mal/Frethog-B also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
ALYacGen:Variant.Zusy.360836
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Injector.9248d57d
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
CyrenW32/CoinMiner.CP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Variant.Zusy.360836
NANO-AntivirusTrojan.Win32.Copak.jbqucr
ViRobotTrojan.Win32.Z.Injector.1391104.BHQ
MicroWorld-eScanGen:Variant.Zusy.360836
TencentWin32.Trojan.Copak.Oyyd
Ad-AwareGen:Variant.Zusy.360836
SophosMal/Frethog-B
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34170.unW@aOrsNaf
VIPREPacker.NSAnti.Gen (v)
FireEyeGeneric.mg.4303b653b0dca78a
EmsisoftGen:Variant.Zusy.360836 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ULPM.Gen
eGambitUnsafe.AI_Score_86%
Antiy-AVLTrojan/Generic.ASCommon.1FB
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataGen:Variant.Zusy.360836
AhnLab-V3Trojan/Win.Generic.R420543
McAfeeGenericRXAA-AA!4303B653B0DC
MAXmalware (ai score=88)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector.Generic
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DIN21
RisingTrojan.Kryptik!1.D238 (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Mal/Frethog-B?

Mal/Frethog-B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment